[Freeipa-users] Problem starting smb service after ipa-adtrust-install

2017-04-10 Thread SOLER SANGUESA Miguel
hello I'm unable to start smb after executing ipa-adtrust-install. the execution of ipa-adtrust-install is: [root@hostname ~]# ipa-adtrust-install --enable-compat --add-agents -d The log file for this installation can be found in /var/log/ipaserver-install.log ipa : DEBUG/sbin/ipa-ad

Re: [Freeipa-users] Centos7/IPA4.2 : disable/enable hosts

2017-04-10 Thread Lachlan Musicman
On 11 April 2017 at 00:14, Johan Vermeulen wrote: > Hello All, > > just getting started with FreeIPA and one of the first features I'm trying > is adding hosts, something I can't do in our current > ldap-setup. So I'm looking forward to being able to do this. > But after adding a host, the only w

Re: [Freeipa-users] Centos7/IPA4.2 : disable/enable hosts

2017-04-10 Thread Rob Crittenden
Johan Vermeulen wrote: > Hello All, > > just getting started with FreeIPA and one of the first features I'm > trying is adding hosts, something I can't do in our current > ldap-setup. So I'm looking forward to being able to do this. > But after adding a host, the only way I see to disable it is un

[Freeipa-users] Centos7/IPA4.2 : disable/enable hosts

2017-04-10 Thread Johan Vermeulen
Hello All, just getting started with FreeIPA and one of the first features I'm trying is adding hosts, something I can't do in our current ldap-setup. So I'm looking forward to being able to do this. But after adding a host, the only way I see to disable it is unprovision it. And after doing that,

Re: [Freeipa-users] SSSD setting memcache_timeout on ipa master

2017-04-10 Thread Ronald Wimmer
On 2017-04-10 13:23, Jakub Hrozek wrote: [...] This shouldn't be the case with 1.14+ and wasn't in my testing. Did you remove the cache (really remove, not just expire with sss_cache) after you upgraded from 1.13 to 1.14? If yes, can you run some simple systemtap scripts? I did not upgrade fro

Re: [Freeipa-users] SSSD setting memcache_timeout on ipa master

2017-04-10 Thread Jakub Hrozek
On Mon, Apr 10, 2017 at 01:07:08PM +0200, Ronald Wimmer wrote: > On 2017-04-10 12:16, Lukas Slebodnik wrote: > > [...] > > sssd_be consumed a lot of CPU and produced a lot of I/O in the sssd cache > > directory. After following > > https://jhrozek.wordpress.com/2015/08/19/performance-tuning-sssd-f

Re: [Freeipa-users] SSSD setting memcache_timeout on ipa master

2017-04-10 Thread Ronald Wimmer
On 2017-04-10 12:16, Lukas Slebodnik wrote: [...] sssd_be consumed a lot of CPU and produced a lot of I/O in the sssd cache directory. After following https://jhrozek.wordpress.com/2015/08/19/performance-tuning-sssd-for-large-ipa-ad-trust-deployments/ the problems did nod reappear. Did you try

Re: [Freeipa-users] SSSD setting memcache_timeout on ipa master

2017-04-10 Thread Lukas Slebodnik
On (08/04/17 17:55), Ronald Wimmer wrote: >On 2017-04-08 12:53, Lukas Slebodnik wrote: >> On (04/04/17 09:41), Ronald Wimmer wrote: >> > On 2017-03-31 13:35, Lukas Slebodnik wrote: >> > > On (29/03/17 10:47), Ronald Wimmer wrote: >> > > > Hi, >> > > > >> > > > yesterday I suddenly was unable to us

Re: [Freeipa-users] Password-based authentication with AD users does not work

2017-04-10 Thread Ronald Wimmer
On 2017-04-07 10:28, Sumit Bose wrote: [...] I'm not aware of any limitation here. Have you tried to run 'ipa trust-fetch-domains ad.forest.root' to update the list? If this does not help please add 'log level = 100' to /usr/share/ipa/smb.conf.empty so that it looks like: [global] log